- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2018 12:31 AM - edited 02-21-2020 07:29 AM
Hello Group! how are you this morning? :)
Was wondering if someone can explain to me the below command on ASA
nat (inside,outside) source static *********** destination static ******** no-proxy-arp route-lookup
Basically I know what it does, I only need help with the last 2 lines (no proxy arp and route-lookup)
Thanks
Solved! Go to Solution.
- Labels:
-
NGFW Firewalls
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2018 01:12 AM
no-proxy-arp - starting with 8.4 ASA will enable proxy-arp for all static NAT statements, in cases you do not want the ASA to respond to arp requests for other IPs, you can use the no-proxy-arp option
route-lookup - the ASA does use the NAT rules to route the packets as well, I believe it has to do with the order of operation and it trusts the NAT statement has the correct interfaces configured. If you want the ASA to use only the routing table instead of the NAT rule, you can use the route-lookup option.
HTH,
Bogdan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-09-2018 01:12 AM
no-proxy-arp - starting with 8.4 ASA will enable proxy-arp for all static NAT statements, in cases you do not want the ASA to respond to arp requests for other IPs, you can use the no-proxy-arp option
route-lookup - the ASA does use the NAT rules to route the packets as well, I believe it has to do with the order of operation and it trusts the NAT statement has the correct interfaces configured. If you want the ASA to use only the routing table instead of the NAT rule, you can use the route-lookup option.
HTH,
Bogdan
